Onyx Security Raises $113M to Govern Enterprise AI Agents

Claude
|

The money flowing into artificial intelligence has spent the past two years chasing the models themselves: bigger training runs, faster chips, and the data centers that keep them humming. This week the market pointed its checkbook somewhere quieter but arguably just as consequential. Onyx Security, an Israeli startup building what it calls a control layer for AI agents, announced a $113 million Series B, a round that says less about how smart machines are becoming and more about how nervous enterprises are getting once those machines are turned loose inside their systems.

What Happened

On Wednesday, July 29, Onyx Security disclosed a $113 million Series B led by Bessemer Venture Partners, with participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared. The financing brings the company's total capital raised to roughly $153 million since it was founded about two years ago, and reporting around the deal pegged the new valuation at an estimated $640 million, a figure the company itself declined to confirm. The raise arrived only four months after Onyx stepped out of stealth in March with a $40 million package split between a $35 million Series A led by Conviction and a $5 million seed from Cyberstarts.

Tel Aviv skyline, home to Israel's cybersecurity startup scene
Suicasmo / CC BY-SA 4.0 / Wikimedia Commons

Onyx sells a centralized platform designed to discover, monitor, and rein in the AI tools spreading across corporate networks. Its pitch centers on a "control plane," a supervisory layer that sits above the sprawl of agents an organization deploys and tracks each one's decision-making step by step using the company's own proprietary models. The centerpiece is a component the company calls the Guardian Agent, a watchdog that observes other agents in real time and intervenes when their behavior drifts outside policy, whether that means catching a prompt-injection attempt, flagging a shadow deployment nobody sanctioned, or halting an action before it touches a system it should not.

The company led by chief executive Maxim Bar Kogan, a veteran of Israel's Unit 8200 intelligence corps, alongside chief AI officer and co-founder Gil Elbaz, says the fresh capital will go toward training its proprietary models and expanding its go-to-market operation. Onyx also shared traction numbers meant to show the problem is already at scale: it claims to secure more than 1.1 million agents across 1.8 million employees and to have analyzed some 66.2 million sessions, with revenue quadrupling in the four months since launch.

Why It Matters

For most of the current cycle, "AI security" meant protecting the models from attackers or stopping people from tricking a chatbot into saying something it should not. Onyx is chasing a newer and thornier version of the problem: what happens when an autonomous agent, granted real credentials and real access to email, cloud storage, and internal software, simply does the wrong thing on its own. As agents move from novelty to infrastructure inside large companies, they inherit the permissions of the humans they replace but none of the accountability, and that gap is exactly what a governance layer is meant to close.

Rows of servers glowing inside an enterprise data center
BalticServers.com / CC BY-SA 3.0 / Wikimedia Commons

That framing helps explain why investors were willing to price a four-month-old commercial product at more than half a billion dollars. The wager is not that Onyx has the best individual feature today but that "agent governance" is becoming a distinct security category, the way endpoint protection, cloud security, and identity management each became their own multibillion-dollar markets. Enterprises tend to buy safety before they buy scale; a chief information security officer who cannot see what an agent is doing is unlikely to approve deploying a thousand of them. A supervisory layer that promises visibility and a kill switch is, in that sense, the permission slip that lets the rest of the agent economy proceed.

There is also a strategic signal in who is standing next to Onyx. In June, Anthropic announced an integration with the company to help secure enterprise AI adoption, a notable endorsement from a frontier model developer whose own customers are wrestling with exactly these deployment questions. When the firms building the agents start pointing their enterprise buyers toward a third party to keep those agents in line, it suggests the model vendors themselves see oversight as a separate job best handled by a specialist.

The Reaction

The round did not land in isolation. It arrived in the middle of a visible surge of capital into agent-era security and infrastructure, with recent weeks bringing raises for an agentic security operations startup, an AI-powered email defense company, and an agentic data-pipeline manager, among others. Taken together, the deals read as a bet by the venture community that the next fortunes in enterprise software will be made not only by the companies deploying AI but by the ones cleaning up after it.

Crowds on the expo floor at a major cybersecurity conference
Ixfd64 / CC BY-SA 3.0 / Wikimedia Commons

Investors backing Onyx have been blunt about the thesis, describing agent oversight as one of the defining security categories of the coming decade and casting the control layer as the thing that makes enterprise AI adoption possible at scale rather than a nice-to-have bolted on later. The language is aggressive, but it mirrors a pattern security buyers know well: every wave of new technology that reaches the enterprise eventually spawns a governance industry built to tame it, from the firewalls that followed the internet to the cloud-security posture tools that followed the migration to AWS and Azure.

Skeptics have a fair counterpoint. A control plane is only as trustworthy as the models doing the watching, and asking one set of AI systems to police another raises obvious questions about who watches the watchdog. Onyx's answer is that its supervisory models are purpose-built and narrowly scoped for oversight rather than open-ended generation, but the category is young enough that no vendor has yet proven the approach at the scale its valuations imply.

What Comes Next

Onyx says the Series B will fund two things: deeper investment in the proprietary models that power its monitoring and a broader commercial push to reach enterprises earlier in their agent rollouts. The strategic prize is to become the default checkpoint that a company installs before it scales autonomous systems, the layer that a security team insists on the way it once insisted on antivirus or single sign-on.

A large-screen security operations center staffed by analysts
Unknown photographer / Public domain / Wikimedia Commons

Getting there means competing on two fronts at once. Established security platforms are extending their own product lines toward AI governance, and a crowd of similarly funded startups is racing to define the category's vocabulary and win the first reference customers. Whoever sets the standards that regulators and auditors eventually adopt, around what an agent is allowed to do, how its actions are logged, and what counts as adequate human oversight, will hold a durable advantage, because compliance frameworks tend to calcify around whatever tooling arrives first.

The larger test is whether "agent governance" proves to be a lasting market or a feature that the big platforms absorb. Onyx is betting that the problem is deep and specialized enough to sustain an independent company, and its early traction and model-vendor partnerships give the argument some weight. The next year of renewals, and whether those 1.1 million monitored agents turn into repeatable enterprise contracts, will show whether the bet holds.

Closing Thoughts

The Onyx raise is a small deal by the standards of an industry that now talks in hundreds of billions, but it captures a shift in where the AI story is heading. The first phase was about capability, teaching machines to reason, write, and act. The next phase is about control, and the unglamorous work of making sure that when software starts making decisions on a company's behalf, someone, or something, is accountable for what it does.

An air traffic controller watching a radar screen
U.S. Marines MCAS-I by Lance Cpl. Donald Dugger / Public domain / Wikimedia Commons

That is why a governance startup can command a nine-figure round barely a year into selling anything. The market has decided that trust is the bottleneck for enterprise AI, not intelligence, and that whoever supplies the trust could end up owning a chokepoint as valuable as the models themselves. Whether Onyx becomes that supplier or simply proves the category exists for someone larger to claim, the deal is a reminder that the agent era will be shaped as much by the guardrails as by the engines behind them.

한글 요약

이스라엘 스타트업 오닉스 시큐리티(Onyx Security)가 7월 29일 베서머 벤처 파트너스가 주도한 1억 1,300만 달러 규모의 시리즈 B 투자를 발표했다. 이번 라운드로 누적 조달액은 약 1억 5,300만 달러에 이르렀고, 회사가 공식 확인하지는 않았으나 기업가치는 약 6억 4,000만 달러로 평가된 것으로 전해졌다. 오닉스는 지난 3월 스텔스에서 벗어난 지 불과 넉 달 만에 이 대형 라운드를 성사시켰다.

오닉스가 만드는 것은 기업 내부에 배치된 AI 에이전트를 감시·통제하는 '컨트롤 플레인'이다. 핵심인 가디언 에이전트(Guardian Agent)는 다른 에이전트의 행동을 실시간으로 관찰하다가 정책을 벗어나면 개입해, 프롬프트 인젝션 공격이나 승인되지 않은 '섀도 AI' 배치를 잡아낸다. 회사는 자체 모델로 에이전트의 의사결정을 단계별로 추적하며, 현재 180만 명의 직원에 걸쳐 110만 개 이상의 에이전트를 보호한다고 밝혔다. 6월에는 앤트로픽(Anthropic)이 오닉스와의 통합을 발표하기도 했다.

이번 투자는 AI 경쟁의 무게중심이 '더 똑똑한 모델'에서 '통제 가능한 배치'로 옮겨가고 있음을 보여준다. 자율 에이전트가 실제 권한을 쥐고 핵심 시스템에 접근하면서, 방화벽이나 클라우드 보안처럼 '에이전트 거버넌스'가 독립된 보안 카테고리로 부상하는 모습이다. 관건은 이 시장이 지속 가능한 독자 영역이 될지, 아니면 대형 플랫폼에 흡수될 기능에 그칠지다. 참고: SecurityWeek, Calcalist, Axios.